CVE-2017-7843 – Mozilla: Web worker in Private Browsing mode can write IndexedDB data
https://notcve.org/view.php?id=CVE-2017-7843
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1. Cuando se utiliza el modo Navegación Privada, es posible que un trabajador web escriba datos persistentes en IndexedDB y realice fingerprinting en un usuario de forma única. IndexedDB no debería estar disponible en modo Navegación Privada y estos datos almacenados persistirán en varias sesiones en modo Navegación Privada porque no se borran al cerrar. • http://www.securityfocus.com/bid/102039 http://www.securityfocus.com/bid/102112 http://www.securitytracker.com/id/1039954 https://access.redhat.com/errata/RHSA-2017:3382 https://bugzilla.mozilla.org/show_bug.cgi?id=1410106 https://lists.debian.org/debian-lts-announce/2017/12/msg00003.html https://www.debian.org/security/2017/dsa-4062 https://www.mozilla.org/security/advisories/mfsa2017-27 https://www.mozilla.org/security/advisories/mfsa2017-28 https://access.redhat.com/securit • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer •
CVE-2017-7839
https://notcve.org/view.php?id=CVE-2017-7839
Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57. Caracteres de control precedidos de las URL "javascript:" pegadas en la barra de direcciones pueden hacer que se ignoren los caracteres principales y que se ejecute el código JavaScript pegado en lugar de bloquearse. Esto podría utilizarse en ataques de ingeniería social y auto-Cross-Site Scripting (self-XSS) donde se convence a los usuarios de que copien y peguen texto en la barra de direcciones. • http://www.securityfocus.com/bid/101832 http://www.securitytracker.com/id/1039803 https://bugzilla.mozilla.org/show_bug.cgi?id=1402896 https://www.mozilla.org/security/advisories/mfsa2017-24 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-7833
https://notcve.org/view.php?id=CVE-2017-7833
Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some font sets on the addressbar. The non-Latin character will not be visible to most viewers. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57. Algunos caracteres marcas de vocales árabes e indios se pueden combinar con caracteres latinos en un nombre de dominio para eclipsar caracteres no latinos con algunas familias de fuentes en la barra de direcciones. • http://www.securityfocus.com/bid/101832 http://www.securitytracker.com/id/1039803 https://bugzilla.mozilla.org/show_bug.cgi?id=1370497 https://www.mozilla.org/security/advisories/mfsa2017-24 • CWE-20: Improper Input Validation •
CVE-2017-7834
https://notcve.org/view.php?id=CVE-2017-7834
A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy including the execution of JavaScript. In prior versions when "data:" documents also inherited the context of the original page this would allow for potential cross-site scripting (XSS) attacks. This vulnerability affects Firefox < 57. Una URL "data:" cargada en una nueva pestaña no hereda la política de seguridad de contenido (CSP) de la página original, permitiendo la omisión de la política, incluyendo la ejecución de código JavaScript. Las versiones anteriores, cuando los documentos "data:" también heredaban el contexto de la página original, permitirían ataques Cross-Site Scripting (XSS) potenciales. • http://www.securityfocus.com/bid/101832 http://www.securitytracker.com/id/1039803 https://bugzilla.mozilla.org/show_bug.cgi?id=1358009 https://www.mozilla.org/security/advisories/mfsa2017-24 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-7840
https://notcve.org/view.php?id=CVE-2017-7840
JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting exported HTML file is later opened in a browser this JavaScript will be executed. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks if users were convinced to add malicious tags to bookmarks, export them, and then open the resulting file. This vulnerability affects Firefox < 57. Se puede inyectar código JavaScript en un archivo de marcadores exportado colocando código JavaScript en las etiquetas proporcionadas por el usuario en los marcadores guardados. • http://www.securityfocus.com/bid/101832 http://www.securitytracker.com/id/1039803 https://bugzilla.mozilla.org/show_bug.cgi?id=1366420 https://www.mozilla.org/security/advisories/mfsa2017-24 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •